安全ID : QSA-23-23
Multiple Vulnerabilities in QuMagie
发布日期 : January 6, 2024
通用漏洞披露 : CVE-2023-47559 | CVE-2023-47560
受影响产品: QuMagie 2.2.x
严重程度
Important
状态
已解决
Summary
Two vulnerabilities have been reported to affect QuMagie:
- CVE-2023-47559: If exploited, the cross-site scripting (XSS) vulnerability could allow authenticated users to inject malicious code via a network.
- CVE-2023-47560: If exploited, the OS command injection vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerabilities in the following version:
| Affected Product | Fixed Version |
| QuMagie 2.2.x | QuMagie 2.2.1 and later |
Recommendation
To fix the vulnerabilities, we recommend updating QuMagie to the latest version.
Updating QuMagie
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "QuMagie" and then press ENTER.
QuMagie appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your QuMagie is already up to date. - Click OK.
The system updates the application.
附件
致谢: lebr0nli (Alan Li), working with DEVCORE Internship Program
修订历史:
V1.0 (January 06, 2024) - Published